A Cross-site WebSocket Hijacking (CSWSH) vulnerability found in UniFi OS 2.5 and earlier allows a malicious actor to access certain confidential information by persuading a UniFi OS user to visit a malicious webpage.Affected Products:Cloud Key Gen2Cloud Key Gen2 PlusUNVRUNVR ProfessionalUDMUDM ProfessionalUDM SEUDRMitigation:Update affected products to UniFi OS 3.0.13 or later.

Project Subscriptions

Vendors Products
Cloud Key Gen2 Subscribe
Cloud Key Gen2 Plus Subscribe
Ubiquiti Networks Unifi Dream Machine Subscribe
Ubiquiti Networks Unifi Dream Machine Professional Subscribe
Ubiquiti Networks Unifi Dream Machine Se Subscribe
Unifi Dream Router Subscribe
Unifi Os Subscribe
Unifi Protect Network Video Recorder Subscribe
Unifi Protect Network Video Recorder Professional Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2023-32059 A Cross-site WebSocket Hijacking (CSWSH) vulnerability found in UniFi OS 2.5 and earlier allows a malicious actor to access certain confidential information by persuading a UniFi OS user to visit a malicious webpage.Affected Products:Cloud Key Gen2Cloud Key Gen2 PlusUNVRUNVR ProfessionalUDMUDM ProfessionalUDM SEUDRMitigation:Update affected products to UniFi OS 3.0.13 or later.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 27 Jan 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2025-01-27T16:44:43.627Z

Reserved: 2023-03-15T00:00:00.000Z

Link: CVE-2023-28361

cve-icon Vulnrichment

Updated: 2024-08-02T12:38:24.989Z

cve-icon NVD

Status : Modified

Published: 2023-05-11T22:15:10.187

Modified: 2025-01-27T17:15:12.240

Link: CVE-2023-28361

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses